CVE-2016-7966: Debian Linux

High severity, CVSS 7.3. EPSS: 2.3% chance of exploitation in the next 30 days.

Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML, which greatly reduces the available HTML functionality. Although it is possible to include an HTML comment indicator to hide content.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Fedoraproject Fedora: version 25 only
  • Kde Kmail: up to and including 4.4.0
  • Suse Linux Enterprise: version 12.0 only

Published 2016-12-23. Last modified 2026-06-17.